Cross Site Scripting Vulnerability in SourceCodester Ferry Ticket System
CVE-2026-11338
4.8MEDIUM
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-11338?
A security vulnerability exists in the SourceCodester Ship Ferry Ticket Reservation System's management interface, where an improperly handled username input can be exploited for cross site scripting (XSS). This allows an attacker to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions or disclosure of sensitive information. The exploit can be triggered remotely, making it crucial for users to apply necessary security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Ship Ferry Ticket Reservation System 1.0
